Security Digest: February 2, 2026 - 9 Critical Vulnerabilities

Today's security landscape reveals nine critical vulnerabilities requiring immediate action. These vulnerabilities range from remote code execution to path traversal, affecting diverse systems and services globally.

· 5 min read

Critical Threats Identified on February 2, 2026

Executive Summary

Today's security landscape reveals nine critical vulnerabilities requiring immediate action. These vulnerabilities range from remote code execution to path traversal, affecting diverse systems and services globally.

Critical Vulnerabilities

  • CVE-2026-23515: Command Injection in Signal K Plugin
    • Impact: Execute arbitrary commands on the server.
    • Affected Systems: Signal K set-system-time plugin
    • Immediate Action: Disable the plugin or restrict permissions.
    • Mitigation: Update code to use execFile() and validate inputs.
  • CVE-2026-22778: RCE via vLLM Video Model
    • Impact: Remote code execution via malicious video URLs.
    • Affected Systems: vLLM versions < 0.14.1
    • Immediate Action: Disable video model processing or apply patches.
    • Mitigation: Apply fixes from recent pull requests.
  • CVE-2026-25059: Path Traversal in File Operations
    • Impact: Unauthorized file access and manipulation.
    • Affected Systems: OpenList application
    • Immediate Action: Restrict file operation permissions.
    • Mitigation: Update to secure file handling methods.
  • CVE-2026-24737: PDF Object Injection in jsPDF
    • Impact: Execute arbitrary JavaScript in PDF viewers.
    • Affected Systems: jsPDF versions < 4.1.0
    • Immediate Action: Update to jsPDF@4.1.0.
    • Mitigation: Sanitize input before passing to APIs.
  • CVE-2026-25060: TLS Verification Disabled in OpenList
    • Impact: Vulnerable to MitM attacks.
    • Affected Systems: OpenList default configuration
    • Immediate Action: Enable TLS verification manually.
    • Mitigation: Configure proper TLS settings immediately.
  • CVE-2026-23997: Stored XSS in Observations Field
    • Impact: Execute arbitrary scripts in admin browsers.
    • Affected Systems: FacturaScripts
    • Immediate Action: Sanitize all input fields.
    • Mitigation: Update to latest version with security patches.
  • CVE-2026-25153: Python Code Execution in TechDocs
    • Impact: Execute arbitrary Python code.
    • Affected Systems: TechDocs with runIn: local
    • Immediate Action: Switch to runIn: docker.
    • Mitigation: Upgrade to @backstage/plugin-techdocs-node version 1.13.11 or later.
  • CVE-2026-25223: Content-Type Validation Bypass in Fastify
    • Impact: Bypass request body validation.
    • Affected Systems: Fastify versions before 5.7.2
    • Immediate Action: Upgrade to Fastify v5.7.2.
    • Mitigation: Implement custom hook to validate headers.
  • CVE-2026-24051: Path Hijacking in OpenTelemetry Go SDK
    • Impact: Arbitrary Code Execution via manipulated PATH.
    • Affected Systems: OpenTelemetry Go SDK on macOS
    • Immediate Action: Patch to version 1.40.0.
    • Mitigation: Secure environment variables appropriately.

Previously Alerted

What to Do Now

  1. Review and apply patches for all affected systems immediately.
  2. Verify system configurations to ensure security measures are active.
  3. Monitor system logs for any signs of exploitation or unusual activity.

Related Resources

  • Stay tuned for upcoming blog posts on securing applications and systems.
  • Check official vendor advisories for detailed patch instructions.

Keep reading